Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79672 | MEDIUM | 5.5 | Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation … | Aug 25, 2026 |
| CVE-2026-79671 | MEDIUM | 5.5 | Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to … | Aug 25, 2026 |
| CVE-2026-79670 | MEDIUM | 4.8 | Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers … | Aug 25, 2026 |
| CVE-2026-79669 | MEDIUM | 4.3 | Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access … | Aug 25, 2026 |
| CVE-2026-79668 | MEDIUM | 5.3 | Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows unauthenticated attackers to increment engagement metrics without identity verification or … | Aug 25, 2026 |
| CVE-2026-79667 | HIGH | 7.6 | Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several privileged admin routes. Multiple privileged endpoints (e.g., /api/inbox, /api/panel/comments, … | Aug 25, 2026 |
| CVE-2026-79666 | MEDIUM | 6.5 | Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated user to access system logs. Attackers with valid user sessions … | Aug 25, 2026 |
| CVE-2026-79665 | HIGH | 8.8 | Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireScopes middleware, allowing logged-in non-admin users to access admin endpoints. … | Aug 25, 2026 |
| CVE-2026-79664 | HIGH | 7.4 | Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent … | Aug 25, 2026 |
| CVE-2026-79663 | MEDIUM | 4.8 | Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. … | Aug 25, 2026 |
| CVE-2026-79662 | HIGH | 8.0 | Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against … | Aug 25, 2026 |
| CVE-2026-79661 | MEDIUM | 6.5 | Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter … | Aug 25, 2026 |
| CVE-2026-79660 | MEDIUM | 5.3 | Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers … | Aug 25, 2026 |
| CVE-2026-79659 | HIGH | 7.7 | Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL … | Aug 25, 2026 |
| CVE-2026-79658 | HIGH | 7.5 | Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP … | Aug 25, 2026 |
| CVE-2026-79657 | CRITICAL | 9.8 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers … | Aug 25, 2026 |
| CVE-2026-78864 | MEDIUM | 6.3 | A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey … | Aug 25, 2026 |
| CVE-2026-78684 | MEDIUM | 5.3 | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream … | Aug 25, 2026 |
| CVE-2026-77997 | UNKNOWN | — | Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to … | Aug 25, 2026 |
| CVE-2026-77996 | UNKNOWN | — | Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a … | Aug 25, 2026 |
| CVE-2026-77824 | MEDIUM | 4.9 | The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, … | Aug 25, 2026 |
| CVE-2026-75971 | HIGH | 7.2 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … | Aug 25, 2026 |
| CVE-2026-75908 | MEDIUM | 4.3 | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not … | Aug 25, 2026 |
| CVE-2026-57910 | UNKNOWN | — | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | Aug 25, 2026 |
| CVE-2026-57909 | UNKNOWN | — | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | Aug 25, 2026 |